Display Filter Reference: Message Transfer Part Level 2

Protocol field name: mtp2

Versions: 1.0.0 to 3.0.7

Back to Display Filter Reference

Field name Description Type Versions
mtp2.bib Backward indicator bit Unsigned integer, 1 byte 1.0.0 to 3.0.7
mtp2.bsn Backward sequence number Unsigned integer, 1 byte 1.0.0 to 3.0.7
mtp2.checksum.error MTP2 Frame CheckFCS 16 Error Label 1.12.0 to 3.0.7
mtp2.fcs_16 FCS 16 Unsigned integer, 2 bytes 2.0.0 to 3.0.7
mtp2.fcs_16.status FCS 16 Unsigned integer, 1 byte 2.4.0 to 3.0.7
mtp2.fib Forward indicator bit Unsigned integer, 1 byte 1.0.0 to 3.0.7
mtp2.frame_reset Frame reset Label 3.0.0 to 3.0.7
mtp2.fsn Forward sequence number Unsigned integer, 1 byte 1.0.0 to 3.0.7
mtp2.li Length Indicator Unsigned integer, 1 byte 1.0.0 to 3.0.7
mtp2.li.bad Bad length indicator value Label 2.6.0 to 3.0.7
mtp2.msg.fragment Message fragment Frame number 3.0.0 to 3.0.7
mtp2.msg.fragment.count Message defragmentation count Frame number 3.0.0 to 3.0.7
mtp2.msg.fragment.error Message defragmentation error Frame number 3.0.0 to 3.0.7
mtp2.msg.fragment.multiple_tails Message has multiple tail fragments Boolean 3.0.0 to 3.0.7
mtp2.msg.fragment.overlap Message fragment overlap Boolean 3.0.0 to 3.0.7
mtp2.msg.fragment.overlap.conflicts Message fragment overlapping with conflicting data Boolean 3.0.0 to 3.0.7
mtp2.msg.fragment.too_long_fragment Message fragment too long Boolean 3.0.0 to 3.0.7
mtp2.msg.fragments Message fragments Label 3.0.0 to 3.0.7
mtp2.msg.reassembled.in Reassembled in Frame number 3.0.0 to 3.0.7
mtp2.msg.reassembled.length Reassembled length Unsigned integer, 4 bytes 3.0.0 to 3.0.7
mtp2.res Reserved Unsigned integer, 2 bytes 1.0.0 to 3.0.7
mtp2.sf Status field Unsigned integer, 1 byte 1.0.0 to 3.0.7
mtp2.sf_extra Status field extra octet Unsigned integer, 1 byte 1.2.0 to 3.0.7
mtp2.spare Spare Unsigned integer, 1 byte 1.0.0 to 3.0.7
mtp2.unexpected_end Unexpected packet end Label 3.0.0 to 3.0.7
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ AppResponse 11
  • • Full stack analysis – from packets to pages
  • • Rich performance metrics & pre-defined insights for fast problem identification/resolution
  • • Modular, flexible solution for deeply-analyzing network & application performance
Learn More